Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
293 articles by Johnie T Young
Amazon scrapped KiroRank after staff gamed it with tokenmaxxing. Build AI adoption metrics that reward outcomes, not fake usage volume.
Which AI tools trigger BIPA in 2026? Facial recognition, voice, and video-interview tools need written consent, a retention schedule, and a no-sale rule.
Colorado replaced its original AI Act with SB 26-189, signed May 14, 2026. The new law drops bias audits and impact assessments in favor of a lighter notice-and-transparency framework. Effective January 1, 2027, it requires pre-use notice, post-adverse-action notice within 30 days, and 3-year recordkeeping for any employer using AI in hiring, promotions, or terminations.
A self-spreading worm compromised 57 npm packages in under 2 hours using binding.gyp instead of postinstall scripts, bypassing security scanners. What it means for teams that run npm install, and the 5 controls that limit your exposure.
Hackers social-engineered Meta AI into resetting passwords on high-profile Instagram accounts by simply asking. What the attack means for any team deploying an AI chatbot that can take account actions, and the 6 controls that prevent it.
EU AI Act Omnibus confirmed June 29, 2026 -- standalone high-risk to Dec 2, 2027, embedded products to Aug 2, 2028. Article 50 still applies Aug 2, 2026.
AI now writes a large share of the pull requests your team reviews. A copy-paste policy and 9-point checklist for reviewing AI-generated PRs, who is accountable, what to require, and where AI code fails review.
5 token budget controls to stop runaway AI bills. Copy-paste usage caps, alerts, per-seat limits, and a kill switch for AI spend governance.
Searching for popular AI tools now surfaces fake malware sites and typosquatted packages at the top of results. A 7-step vetting check to confirm an AI tool is the real one before your team installs it.
When your AI agent sends a wrong email, makes a bad purchase, or deletes data, the law says you are responsible, not the AI. Here is what small teams must do before deploying autonomous agents in 2026.
Can your AI agent erase a user from its vector database? Spanish regulators found most cannot. Fix AI agent GDPR memory compliance before an audit.
Which AI providers indemnify your output? Compare policies and use this pre-publish checklist to manage AI output copyright risk in 2026.